skills/hk-hub/agentskills/build-mcpb/Gen Agent Trust Hub

build-mcpb

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references manifest schemas and tooling (such as @anthropic-ai/mcpb) from the official Anthropics GitHub organization and public registries.
  • [COMMAND_EXECUTION]: Provides standard build and packaging command examples for bundling MCP servers, such as npx @anthropic-ai/mcpb pack and npm install.
  • [DATA_EXFILTRATION]: Includes code examples for local file access (list_files, read_file), which are the intended primary purpose of a local MCP server. The skill provides explicit security documentation in references/local-security.md detailing how to prevent path traversal and validate access boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — build-mcpb